sap

1,568 tracked vulnerabilities.

CVE-2018-2445 CRITICAL
SAP BusinessObjects Business Intelligence 4.1, 4.2 - Server-Side Request Forgery
Aug 14, 2018
CVSS 9.6
EPSS 0.00
CVE-2018-2444 MEDIUM
SAP BusinessObjects Financial Consolidation 10.0 10.1 - Cross-Site Scripting
Aug 14, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-2442 HIGH
SAP BusinessObjects Business Intelligence 4.0-4.2 - Cross-Site Request Forgery
Aug 14, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-2441 MEDIUM
SAP Kernel 7.21-7.22, 7.21EXT-7.22EXT, 7.45, 7.49, 7.53, 7.73 - Information Disclosure in Change and Transport System
Aug 14, 2018
CVSS 5.5
EPSS 0.00
CVE-2018-2440 MEDIUM
SAP Dynamic Authorization Management - Sensitive Information Exposure in Application Logs
Jul 10, 2018
CVSS 4.4
EPSS 0.00
CVE-2018-2439 MEDIUM
SAP Internet Graphics Server 7.20, 7.20EXT, 7.45, 7.49, 7.53 - Denial of Service via Malformed Data Packet
Jul 10, 2018
CVSS 5.9
EPSS 0.00
CVE-2018-2438 HIGH
SAP Internet Graphics Server 7.20 7.20EXT 7.45 7.49 7.53 - Denial of Service
Jul 10, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-2437 CRITICAL
SAP Internet Graphics Service 7.20 7.20EXT 7.45 7.49 7.53 - Remote Code Execution
Jul 10, 2018
CVSS 9.1
EPSS 0.01
CVE-2018-2436 HIGH
SAP R/3 Enterprise Retail - Missing Authorization in WRCK Transaction
Jul 10, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-2435 MEDIUM
SAP NetWeaver Enterprise Portal 7.0-7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 - Cross-Site Scripting
Jul 10, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-2434 MEDIUM
SAP NetWeaver UI Add-on and SAP UI Implementation - Content Spoofing via HTML Page Rendering
Jul 10, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-2433 HIGH
SAP Kernel 7.21-7.22, 7.21EXT-7.22EXT, 7.45, 7.49, 7.53 - Denial of Service
Jul 10, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-2432 MEDIUM
SAP BusinessObjects Business Intelligence 4.10-4.30 - Cross-Site Scripting via HTTP Response Header
Jul 10, 2018
CVSS 5.4
EPSS 0.00
CVE-2018-2431 MEDIUM
SAP BusinessObjects Business Intelligence Suite 4.10 and 4.20 - Cross-Site Scripting
Jul 10, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-2427 HIGH
SAP BusinessObjects Business Intelligence Suite 4.10-4.20 - Code Injection
Jul 10, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-2428 MEDIUM
SAP UI5 Handler - Information Disclosure
Jun 12, 2018
CVSS 5.3
EPSS 0.00
CVE-2018-2425 HIGH
SAP Business One <9.3 - Info Disclosure
Jun 12, 2018
CVSS 8.4
EPSS 0.00
CVE-2018-2424 CRITICAL
SAP UI5 - Cross-Site Scripting via DOM Injection
Jun 12, 2018
CVSS 9.8
EPSS 0.00
CVE-2018-11415 MEDIUM
SAP Internet Transaction Server 6200.X.X - Reflected Cross-Site Scripting via wgate URIs
May 24, 2018
CVSS 6.1
EPSS 0.03
CVE-2018-2423 MEDIUM
SAP Internet Graphics Server 7.20 7.20EXT 7.45 7.49 7.53 - Denial of Service
May 09, 2018
CVSS 5.3
EPSS 0.01
CVE-2018-2422 MEDIUM
SAP Internet Graphics Server 7.20, 7.20EXT, 7.45, 7.49, 7.53 - Denial of Service
May 09, 2018
CVSS 5.3
EPSS 0.01
CVE-2018-2421 MEDIUM
SAP Internet Graphics Server 7.20 7.20EXT 7.45 7.49 7.53 - Denial of Service via Portwatcher
May 09, 2018
CVSS 5.3
EPSS 0.01
CVE-2018-2420 MEDIUM
SAP Internet Graphics Server 7.20 7.20EXT 7.45 7.49 7.53 - Unrestricted Upload of File with Dangerous Type
May 09, 2018
CVSS 6.5
EPSS 0.01
CVE-2018-2419 LOW
SAP Enterprise Financial Services - Missing Authorization
May 09, 2018
CVSS 3.7
EPSS 0.00
CVE-2018-2418 MEDIUM
SAP MaxDB ODBC Driver < 7.9.09.07 - Code Injection
May 09, 2018
CVSS 5.5
EPSS 0.00